Interesting Shodan searches: Dedicated Micros DVRs

This one was found just browing “port:23 country:GB” results.

It appears that SD Advanced DVRs don’t always require a username and password to get into them  – “SD Advanced Closed IPTV -usernameScreen Shot 2015-05-16 at 10.47.45 Screen Shot 2015-05-16 at 10.47.31

Yeah. Let’s look at the manuals.
Screen Shot 2015-05-16 at 16.28.54

So that’s no username or password by default.

Screen Shot 2015-05-16 at 16.30.23

And an ini file with credentials of other devices. Great!

At least the manual doesn’t explicitly recommend you setup portfowarding as well…

It seems it’s not just this line made by Dedicated Micros – Ecosense does it as well. In fact, it’s pretty much every one they seem to make. 459 open DVRs in the UK alone.

